Use readline for the token prompt to prevent paste leaking into shell

Plain `read -rsp` has no paste awareness: a token with a trailing
newline (common from some "copy token" UI buttons) terminates the
read early, and whatever came after in the paste is left in the
terminal's input buffer - which the shell then executes as a command
once the script exits. `read -e` uses GNU readline, which honors
bracketed paste and inserts a multi-line paste as literal text
instead of treating embedded newlines as Enter.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tommy Rantti 2026-09-26 20:15:14 +03:00
parent 254afd67fa
commit 07c02bb512

View file

@ -279,7 +279,7 @@ forgejo_ssh_key() {
echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's" echo "scope (or tick 'user' read+write) -> Generate Token -> copy it now, it's"
echo "only shown once." echo "only shown once."
local token local token
read -rsp "Forgejo access token (used once, not stored): " token read -r -s -e -p "Forgejo access token (used once, not stored): " token
echo echo
token="${token//[[:space:]]/}" token="${token//[[:space:]]/}"
if [ -z "$token" ]; then if [ -z "$token" ]; then